# Environment variables

Every setting of the stack's .env, what it does, its default and the services that read it.

Settings for docker compose. `make .env` copies this file to .env and fills in the empty secrets; run again after this file gains a setting, it adds only what .env lacks. By hand, generate each secret with `openssl rand -hex 32` (APP_KEY: "base64:" followed by `openssl rand -base64 32`).

- `APP_KEY` (required): The control plane's encryption key. Read by [`control`](/docs/reference/services#control).

- `APP_URL` (default: `http://localhost:8000`): Where merchants open the panel. Read by [`control`](/docs/reference/services#control).

Postgres: the superuser only sets up the roles; the control plane, the indexer and the Query API have one each.

- `POSTGRES_PASSWORD` (required): Read by [`postgres`](/docs/reference/services#postgres).

- `DB_PASSWORD` (required): Read by [`postgres`](/docs/reference/services#postgres), [`control`](/docs/reference/services#control).

- `INDEXER_DB_PASSWORD` (required): Read by [`postgres`](/docs/reference/services#postgres), [`indexer`](/docs/reference/services#indexer).

- `QUERY_DB_PASSWORD` (required): Read by [`postgres`](/docs/reference/services#postgres), [`orbsearch`](/docs/reference/services#orbsearch).

- `MEILI_MASTER_KEY` (required): At least 16 bytes. Only the indexer holds it. Read by [`meilisearch`](/docs/reference/services#meilisearch), [`indexer`](/docs/reference/services#indexer).

- `MEILI_SEARCH_KEY` (required): The Query API's key, which may only search and list indexes; the indexer creates it from the master key at start. `make .env` derives it; by hand, it is the master key's HMAC of the key's uid: `printf %s 5e7d2c4a-8f1b-4c3e-9a6d-0b2f4e6a8c1d | openssl dgst -sha256 -hmac "$MEILI_MASTER_KEY"` Read by [`orbsearch`](/docs/reference/services#orbsearch).

- `ORBSEARCH_MANAGEMENT_KEY` (required): Authorizes the management API: `Authorization: Bearer <key>`. Read by [`control`](/docs/reference/services#control).

The panel and the Query API listen on this host address. 127.0.0.1 keeps them for a proxy on this machine, which also terminates TLS; 0.0.0.0 opens them to the network.

- `PUBLISH_ADDRESS` (default: `127.0.0.1`): Read by [`orbsearch`](/docs/reference/services#orbsearch), [`control`](/docs/reference/services#control).

- `CONTROL_PORT` (default: `8000`): Read by [`control`](/docs/reference/services#control).

- `ORBSEARCH_PORT` (default: `7800`): Read by [`orbsearch`](/docs/reference/services#orbsearch).

Postgres and Meilisearch listen on 127.0.0.1 only.

- `POSTGRES_PORT` (default: `5432`): Read by [`postgres`](/docs/reference/services#postgres).

- `MEILISEARCH_PORT` (default: `7700`): Read by [`meilisearch`](/docs/reference/services#meilisearch).

- `DEMO_PORT` (default: `3000`): The demo storefront, which `make e2e` serves on the host for its browser tests. Read by [`control`](/docs/reference/services#control).

- `SHOP_URL` (default: `http://localhost:${DEMO_PORT:-3000}` · example: `https://shop.example`): Where the shop answers, so the panel's previews show its photos; the demo storefront at DEMO_PORT when unset. Read by [`control`](/docs/reference/services#control).

- `ORBSEARCH_FEEDS_FROM_PRIVATE_NETWORKS` (default: `false`): The catalog source's feed is fetched from the public internet only. true also fetches from private, loopback and link-local addresses, such as a feed on this machine or on the shop's own network; `make stack` sets it. Read by [`control`](/docs/reference/services#control).

- `TRUSTED_PROXIES`: Behind a proxy that terminates TLS: its addresses, comma-separated. Never `*`. Read by [`control`](/docs/reference/services#control).

A real mailer turns on email verification; without one, mail goes to the log.

- `MAIL_MAILER` (example: `smtp`): Read by [`control`](/docs/reference/services#control).

- `MAIL_SCHEME`: Read by [`control`](/docs/reference/services#control).

- `MAIL_HOST`: Read by [`control`](/docs/reference/services#control).

- `MAIL_PORT`: Read by [`control`](/docs/reference/services#control).

- `MAIL_USERNAME`: Read by [`control`](/docs/reference/services#control).

- `MAIL_PASSWORD`: Read by [`control`](/docs/reference/services#control).

- `MAIL_FROM_ADDRESS`: Read by [`control`](/docs/reference/services#control).

- `AI_GATEWAY_API_KEY`: Optional: a Vercel AI Gateway key turns on mapping suggestions in the import panel (model typesafe-ai/jev). Without it, the panel maps with the import's own rules only. Read by [`orbsearch`](/docs/reference/services#orbsearch).

**Guide:** [Settings](/docs/self-hosting#settings)
